Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2023-26121 Vulnerability in npm package safe-eval
CVE-2023-33510 Vulnerability in maven package org.jeecgframework.p3:jeecg-p3-biz-chat
CVE-2021-3645 Vulnerability in npm package @viking04/merge
CVE-2021-3632 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2019-3580 Vulnerability in maven package org.openrefine:openrefine